Vulnerability record · CVE-2022-25075 · published 24 February 2022
CVE-2022-25075: TOTOLink A3000RU router command injection via QUERY_STRING
TTotolink · A3000ru Firmware
TOTOLink A3000RU firmware V5.9c.2280_B20180512 contains an OS command injection flaw in the "Main" function, reachable through the QUERY_STRING parameter. Successful exploitation lets an attacker run arbitrary commands on the device, which is severe for an internet-facing router. The record does not state which firmware builds are fixed beyond the referenced patch link.
Description
TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, plus public exploit code and a very high EPSS score, make this an urgent fix for any exposed A3000RU.
What it is
TOTOLink A3000RU firmware V5.9c.2280_B20180512 contains an OS command injection flaw in the "Main" function, reachable through the QUERY_STRING parameter. Successful exploitation lets an attacker run arbitrary commands on the device, which is severe for an internet-facing router. The record does not state which firmware builds are fixed beyond the referenced patch link.
Impact
An attacker gains arbitrary command execution on the router, allowing full compromise of the device, its configuration and any traffic or credentials it handles. Given the network vector and no required privileges, this can be leveraged for lateral movement into the network it serves.
Attack surface
The flaw is reached over the network via the QUERY_STRING parameter (CVSS AV:N, PR:N, UI:N), so no authentication or user interaction is needed. Any exposed management or web interface on the affected firmware is a potential entry point.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at roughly 0.56 (99th percentile) and the reference is tagged Exploit, indicating public exploit code exists. No ransomware association is documented.
What to do
- Apply the vendor patch or upgrade to a fixed firmware build; the reference is tagged Patch, so check TOTOLink's advisory for the corrected version.
- If no patch is available, remove the device's management interface from the internet and restrict access to a trusted management VLAN or allowlisted hosts.
- Disable remote administration and any unused WAN-facing services on the router.
- Replace end-of-life firmware with a supported device if the vendor no longer issues updates.
- Monitor the device for unexpected outbound connections or command execution artifacts until patched.
Detection
- Inspect web server and router logs for requests with suspicious characters or shell metacharacters in the QUERY_STRING parameter.
- Alert on unexpected processes or outbound connections originating from the router's management interface.
- Watch for repeated or malformed requests to the affected endpoint from external or untrusted source IPs.
- Compare running firmware version against the vendor's fixed release to identify unpatched devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/EPhaha/IOT_vuln/blob/main/TOTOLink/A3000RU/README.md | ExploitPatchThird Party Advisory |
| https://github.com/EPhaha/IOT_vuln/blob/main/TOTOLink/A3000RU/README.md | ExploitPatchThird Party Advisory |
Track CVE-2022-25075 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-25075), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.